Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (read-only, idempotent, non-destructive), the description adds 'Execution: synchronous' and 'Task support: forbidden', and clarifies that 'The returned JSON is internal application state' not meant for direct display. It also instructs the agent to summarize and suggest next actions, which is valuable behavioral context. No contradictions with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.